{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e2dc8109-2fa5-5260-9143-50cad2e6d786",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "5.3.37-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c7cfb8bb-28fd-54cd-8550-f11124019cd4",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6df3d1-6b90-5186-80c2-9cd2f3db64db",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4359007a-f8ff-5408-ae67-01eca44a7ae9",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52be7314-ca1c-533f-8cb8-11ee63ef9b5d",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eebc8601-03b8-5704-896f-be15c70ae6d7",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95692eba-df8f-5bfc-89bf-533dfc524b0c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98aee43e-0a10-59d9-9a5e-0c587381e2cc",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ecaa17d-04e8-5cc2-88b8-e52e8228adc1",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a2f39df-9fd4-582c-8d70-d3dfb8203ef3",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09cc0f17-d837-5a4c-abe5-82e248a29de7",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6493788d-10be-566f-bfcc-d1ac3f599c14",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f5eadaf-d49d-5bad-8bfd-9c10b9cdb939",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebf8cf2d-1e45-5908-8b5a-7e069c9b7ef9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:261ec0aa-766c-5726-9b02-7cd83ce010f5",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:839bf7c2-70ea-51c2-8c65-7b5ff1122a8e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85ae8318-d136-57a0-b962-9c37cf1ff11e",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5eded9d-1657-5a77-ac73-57415aa371a6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76753bd7-bdc7-53eb-9a16-3b5d27a0c258",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f737fc5-584b-56fe-b367-e252a124f531",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-expression. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c235d949-ff3a-56f3-a7dd-345676b1644d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37a15f34-03a2-5c93-be0e-bac919cdbbd5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b37aa3e-5084-582d-abbf-e4eba1f53b9e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3820ed6d-48b4-58c9-9671-fc88c87cbfe7",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3b9e395-3dc4-5e1f-8e0b-9d08c4496a80",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:025f2185-76f8-5743-a447-4206bf0cd55e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65a761b6-19a9-5155-81ab-04a89fa9b7e4",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a1c955a-420f-52c2-a9a8-49b33b03f9cc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63589e45-09f9-58ad-92c4-19c0b9542c05",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-expression. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecea1d79-df1f-5c12-aa9c-0c0405faf54d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19a60831-5280-548c-904a-80ae66f8d05a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67cf4524-d2cf-5eeb-af53-7e0ff77c7f09",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4758a95a-e7b4-5c62-85f9-c90551d412c4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad91460d-adee-5228-920a-ac6573b8c0c1",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.37-tuxcare.2"
    }
  ]
}